🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104402 Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105086 WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting ... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105224 YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering u... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105089 WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105158 A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseCo... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105215 ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105214 Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105213 ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user'... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105212 ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or othe... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105211 ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtai... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105210 ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and i... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105209 ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment code... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105208 ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users t... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105207 ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary f... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105206 ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105205 SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105157 A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105156 A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105149 A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105148 A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the ... | MEDIUM | ????? | ????? | NVD | 2 days ago |